DFARS 7012 Compliance: What the Clause Requires of Contractors

DFARS 7012 compliance has been the baseline expectation for defense contractors handling sensitive information for years, and yet the clause is regularly misread as a single requirement when it is really several distinct obligations bundled together. DFARS clause 252.204-7012 requires a contractor to safeguard covered defense information, to report cyber incidents quickly, to ensure any cloud it uses meets a specific standard, and to pass the same obligations down to its subcontractors. Missing any one of these is a compliance gap. This guide walks through what the clause actually requires, how each obligation works, and how it all connects to CMMC. The reason the clause matters so much is that it is the contractual hook for defense cybersecurity. It is where the requirement to implement a security standard becomes a binding term of your contract rather than a recommendation, and it is the mechanism that has obliged contractors to protect controlled unclassified information since well before CMMC arrived. Understanding it is the foundation for understanding everything that has been built on top of it. What DFARS 7012 Requires The clause sets out several related obligations, and treating them as a checklist rather than a single duty is the key to genuine compliance. Each one stands on its own, and an assessor or a contracting officer can hold you to any of them independently. The Adequate Security Requirement The core obligation is to provide adequate security for covered defense information on covered contractor information systems, and the clause defines adequate security as implementing the requirements of NIST SP 800-171. This is the safeguarding half of the clause: the 110 requirements of the standard are not optional good practice under DFARS 7012, they are the contractual definition of adequate security. A contractor that has not implemented 800-171 has not met the clause, which is why the standard and the clause are so tightly bound together. Working through the standard is the subject of the NIST 800-171 compliance checklist. Cyber Incident Reporting Within 72 Hours The clause also imposes a strict reporting duty. When a contractor discovers a cyber incident affecting a covered system or the covered defense information on it, it must report the incident to the Department of War within 72 hours of discovery, through the DIBNet portal. The obligation does not end with the report: the clause requires preserving and protecting images of the affected systems so evidence is available, commonly for a defined retention period, submitting any malicious software discovered, and providing the access needed for a forensic review. Because the clock runs from discovery rather than resolution, this is one of the obligations most likely to catch an unprepared contractor, and it is covered in depth in the guide to CMMC incident response. Cloud Service Provider Equivalency If a contractor uses an external cloud service to store, process, or transmit covered defense information, DFARS 7012 requires that cloud to meet security requirements equivalent to the FedRAMP Moderate baseline. The operative standard for the cloud is that FedRAMP Moderate equivalency, measured against the FedRAMP Moderate control set rather than against 800-171 directly, and it is demonstrated through a third-party assessment by a 3PAO that produces a body of evidence covering that control set. This is a distinct obligation that stacks with your own implementation of 800-171 rather than replacing it: the cloud must reach its equivalency, and you must still meet your contractor requirements. The detail of how that equivalency is established is covered in the guide to FedRAMP equivalency. Flowdown to Subcontractors Finally, the clause must flow down. A contractor is required to include the substance of DFARS 7012 in subcontracts where subcontractors will handle covered defense information, which means your compliance depends partly on theirs. This flowdown is easy to overlook and consequential when it is, because an incident or a gap in a subcontractor’s environment can become your problem when the covered defense information is yours. Managing the clause therefore means managing your supply chain, not just your own systems. How DFARS 7012 Connects to CMMC DFARS 7012 and CMMC are closely related but do different jobs, and understanding the relationship prevents a common confusion. DFARS 7012 requires you to implement 800-171 and to attest to that implementation yourself, historically on trust. CMMC, applied through a separate clause, adds the verification layer that confirms the self-attestation is real, assigning a certification level based on an assessment rather than relying on the contractor’s word alone. In other words, DFARS 7012 established the obligation and the self-attestation, and CMMC adds the assessment teeth. The security work is the same under both, because both rest on 800-171, but the accountability differs. For a fuller treatment of how the standard and the verification framework relate, the guide to NIST 800-171 versus CMMC draws the distinction in detail. The practical point for a contractor is that DFARS 7012 compliance is the durable foundation, and CMMC is the verification that increasingly sits on top of it. DFARS 7012 Compliance Under the Current Suspension The 2026 suspension of third-party CMMC assessment has led some contractors to relax, and where DFARS 7012 is concerned that is a mistake. DFARS 7012 is a contractual clause in your existing contracts, not a step in the CMMC certification process, so it is entirely unaffected by the suspension. The duty to safeguard covered defense information, the 72-hour reporting obligation, the cloud equivalency requirement, and the flowdown to subcontractors all remain fully in force today. The suspension paused the third-party verification layer, but it did nothing to the clause that underlies it. A contractor can be correct that its CMMC certification assessment is on hold and still owe every obligation in DFARS 7012, including a 72-hour incident report the moment an incident is discovered. If anything, the suspension makes DFARS 7012 compliance more prominent, because it is the live, enforceable cybersecurity obligation in your contracts while the certification layer waits. What DFARS 7012 Compliance Requires of You in Practice In practical terms, DFARS 7012 compliance comes down to